LWN.net Logo

ldapscripts: password disclosure

Package(s):ldapscripts CVE #(s):CVE-2007-5373
Created:March 17, 2008 Updated:March 19, 2008
Description:

From the Debian advisory:

Don Armstrong discovered that ldapscripts, a suite of tools to manipulate user accounts in LDAP, sends the password as a command line argument when calling LDAP programs, which may allow a local attacker to read this password from the process listing.

Alerts:
Debian DSA-1517-1 2008-03-15

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.